From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 73905392811 for ; Wed, 7 Jan 2026 15:28:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767799716; cv=none; b=TomqgQ+cIPd3tgx2d/FTH0uzegYnV4lsy/U8uaScKc1FR0j81xcScSqNgX2VWDa5nMvSdI3A/toYQlrjjX/bUfoFoo94dVXu+m9TTGtPfnV4Q1JgsGWNdCwNHuS0W8Y7Vwo9eW02j7Seu9yRSlJa5CDG1GSACkMKqsbvLKdb6rw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767799716; c=relaxed/simple; bh=RQ6L+iRakCIIVZ4Q8VvzEgXIqB+VcJtyWBzjUhiDWnM=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=QMf+CmXBI8HpifpubQDFD3zTm9TiIXSKdA602tC/v597h/m/aVT4mroBkdv06CuJg/u/XMF3XidgBD9ORECUNLVGHIu6IwaSIagml1Tqu4dy7N863jJU2gG9UJaLAq0tcynPB1IOnzO/PdlakYoXAZ7jvVQeL6Lzi+jDdDuZb2Q= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=GajhOGnC; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="GajhOGnC" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D8816C4CEF1; Wed, 7 Jan 2026 15:28:34 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1767799715; bh=RQ6L+iRakCIIVZ4Q8VvzEgXIqB+VcJtyWBzjUhiDWnM=; h=Date:Subject:To:Cc:References:From:In-Reply-To:From; b=GajhOGnCpKrjaiYDZ0hwZTouNTMoBtWbF7UQcFHjKvTR6Nk0IvtTHQorIuG+UuDFY Rl1r6EHjI9OkzL6Nb/Yfnq1rECXl3aax47UrW1sU3TDxFVNIqoZCWawYM5T6PtahDd uBRqrEfI3ZOUWPnb/PE0MRq2AZwu6Xp/lgWPobFf5+QNAwCkCLkp6bSLeKPOH54acU nHA1TGmS/QLxKJyucjrCEWGL0/t2OZS+NzAhJYWV9FM4/7gHK1vvMpGDTWCZ7RFnK8 P6NKV65zZPJEBrXMXpFzym3v0QdIgGG/obQifZSCZYwzIyXAqFpF0+qbqgUWjSGAvo cPRkjlr0sP+UA== Message-ID: <2f4b30fd-8e0a-4482-9bab-a90e32e69839@kernel.org> Date: Wed, 7 Jan 2026 09:28:34 -0600 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v5 1/2] tee: add revision sysfs attribute To: Aristo Chen , linux-kernel@vger.kernel.org Cc: jens.wiklander@linaro.org, sumit.garg@kernel.org, op-tee@lists.trustedfirmware.org, harshal.dev@oss.qualcomm.com, Rijo-john.Thomas@amd.com, amirreza.zarrabi@oss.qualcomm.com, Aristo Chen References: <20251230051804.6230-1-aristo.chen@canonical.com> <20260107152607.902735-1-aristo.chen@canonical.com> Content-Language: en-US From: Mario Limonciello In-Reply-To: <20260107152607.902735-1-aristo.chen@canonical.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit On 1/7/26 9:26 AM, Aristo Chen wrote: > Add a generic TEE revision sysfs attribute backed by a new > optional get_tee_revision() callback. The revision string is > diagnostic-only and must not be used to infer feature support. > > Signed-off-by: Aristo Chen > --- > Documentation/ABI/testing/sysfs-class-tee | 10 +++++ > drivers/tee/tee_core.c | 51 ++++++++++++++++++++++- > include/linux/tee_core.h | 9 ++++ > 3 files changed, 69 insertions(+), 1 deletion(-) > > diff --git a/Documentation/ABI/testing/sysfs-class-tee b/Documentation/ABI/testing/sysfs-class-tee > index c9144d16003e..6e783210104e 100644 > --- a/Documentation/ABI/testing/sysfs-class-tee > +++ b/Documentation/ABI/testing/sysfs-class-tee > @@ -13,3 +13,13 @@ Description: > space if the variable is absent. The primary purpose > of this variable is to let systemd know whether > tee-supplicant is needed in the early boot with initramfs. > + > +What: /sys/class/tee/tee{,priv}X/revision > +Date: Dec 2025 > +KernelVersion: 6.18 This needs to be bumped up and dates pushed out. > +Contact: op-tee@lists.trustedfirmware.org > +Description: > + Read-only revision string reported by the TEE driver. This is > + for diagnostics only and must not be used to infer feature > + support. Use TEE_IOC_VERSION for capability and compatibility > + checks. > diff --git a/drivers/tee/tee_core.c b/drivers/tee/tee_core.c > index d65d47cc154e..0a00499811c1 100644 > --- a/drivers/tee/tee_core.c > +++ b/drivers/tee/tee_core.c > @@ -1146,7 +1146,56 @@ static struct attribute *tee_dev_attrs[] = { > NULL > }; > > -ATTRIBUTE_GROUPS(tee_dev); > +static const struct attribute_group tee_dev_group = { > + .attrs = tee_dev_attrs, > +}; > + > +static ssize_t revision_show(struct device *dev, > + struct device_attribute *attr, char *buf) > +{ > + struct tee_device *teedev = container_of(dev, struct tee_device, dev); > + char version[TEE_REVISION_STR_SIZE]; > + int ret; > + > + if (!teedev->desc->ops->get_tee_revision) > + return -ENODEV; > + > + ret = teedev->desc->ops->get_tee_revision(teedev, version, > + sizeof(version)); > + if (ret) > + return ret; > + > + return sysfs_emit(buf, "%s\n", version); > +} > +static DEVICE_ATTR_RO(revision); > + > +static struct attribute *tee_revision_attrs[] = { > + &dev_attr_revision.attr, > + NULL > +}; > + > +static umode_t tee_revision_attr_is_visible(struct kobject *kobj, > + struct attribute *attr, int n) > +{ > + struct device *dev = kobj_to_dev(kobj); > + struct tee_device *teedev = container_of(dev, struct tee_device, dev); > + > + if (teedev->desc->ops->get_tee_revision) > + return attr->mode; > + > + return 0; > +} > + > +static const struct attribute_group tee_revision_group = { > + .attrs = tee_revision_attrs, > + .is_visible = tee_revision_attr_is_visible, > +}; > + > +static const struct attribute_group *tee_dev_groups[] = { > + &tee_dev_group, > + &tee_revision_group, > + NULL > +}; > > static const struct class tee_class = { > .name = "tee", > diff --git a/include/linux/tee_core.h b/include/linux/tee_core.h > index 1f3e5dad6d0d..ee5f0bd41f43 100644 > --- a/include/linux/tee_core.h > +++ b/include/linux/tee_core.h > @@ -76,6 +76,9 @@ struct tee_device { > /** > * struct tee_driver_ops - driver operations vtable > * @get_version: returns version of driver > + * @get_tee_revision: returns revision string (diagnostic only); Why is this comment here about it being for diagnostics only? I feel it's up to the implementation how it would be used. > + * do not infer feature support from this, use > + * TEE_IOC_VERSION instead > * @open: called for a context when the device file is opened > * @close_context: called when the device file is closed > * @release: called to release the context > @@ -95,9 +98,12 @@ struct tee_device { > * client closes the device file, even if there are existing references to the > * context. The TEE driver can use @close_context to start cleaning up. > */ > + > struct tee_driver_ops { > void (*get_version)(struct tee_device *teedev, > struct tee_ioctl_version_data *vers); > + int (*get_tee_revision)(struct tee_device *teedev, > + char *buf, size_t len); > int (*open)(struct tee_context *ctx); > void (*close_context)(struct tee_context *ctx); > void (*release)(struct tee_context *ctx); > @@ -123,6 +129,9 @@ struct tee_driver_ops { > int (*shm_unregister)(struct tee_context *ctx, struct tee_shm *shm); > }; > > +/* Size for TEE revision string buffer used by get_tee_revision(). */ > +#define TEE_REVISION_STR_SIZE 128 > + > /** > * struct tee_desc - Describes the TEE driver to the subsystem > * @name: name of driver